Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 14 additions & 4 deletions .github/openclaw/release-notes.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,16 @@
This release wakes a passive garbage collector when its mutator starts waiting, allowing collection to progress when shared GC helpers are occupied elsewhere. A native regression checks the late-wait transition, completion before helper release, and survival of rooted objects.
This release fixes two native stack storage paths that could conservatively retain otherwise unreachable objects, including cancellation reasons. Newly created VM entry records now initialize their callee-save scratch buffers and alignment padding. Deferred microtask entry scopes use two initialized pointers instead of an optional engagement byte with stale padding. Lazy entry, global-object updates, unwind state and teardown boundaries remain intact, without a new heap allocation. Native poisoned-storage regressions cover both owners. Thanks @robobun for the related whole-word-state remedy in [oven-sh/WebKit#694](https://github.com/oven-sh/WebKit/pull/694).

Budgeted workers now use young-generation collections and bound post-full-collection growth independently of machine-wide RAM. Full collections still verify heap-limit exhaustion. Idle collection requires the matching immediate GC timer wakeup in [Bun #129](https://github.com/openclaw/bun/pull/129); include that companion when consuming this engine.
This batch also fixes a Linux deadlock when a Worker waits in a native call on a foreign stack, as used by Koffi. Asynchronous VM trap sampling now makes one suspension attempt and releases the process-wide suspension lock before retrying a refused sample. This lets another VM finish collection and release the native call while termination remains pending. Blocking GC suspension still requires a valid stack/register snapshot; Mach suspension retains its existing operation. The native regression checks parent collection before native release, rooted-object survival, pending termination, temporary refusal and nested suspension. General same-VM foreign-stack scanning is outside this fix.

The original Koffi probe timed out in 66 of 200 processes with the released Bun and passed all 200 with the patched engine; each process performs ten Worker terminations. The controlled native regression deadlocks on the original engine and passes with the fix. ASAN passes with its standard incomplete swapcontext-support warning. TSAN remains nonzero: all eight reported signatures were also reproduced by an unpatched two-VM GC control, without suppressions. This is baseline attribution, not a clean TSAN or race-freedom claim.

Qualification now uses the collected-realm FinalizationRegistry fixture merged in [Bun #151](https://github.com/openclaw/bun/pull/151), adapted from [oven-sh/bun#44544](https://github.com/oven-sh/bun/pull/44544); thanks @robobun. It requires at least one realm to be observed collected and zero callbacks for every collected realm. PR and artifact workflows retain the four qualified Linux Bun executables and their hashes for three days, including available executables after a failure. These diagnostics are separate from the immutable release assets.

Both fixes use the existing Bun embedding adapters; the suspension fix needs no new runtime adapter. Consumers still need a joint rebuild with the matching engine headers and libraries.

Previously released fixes remain included. The engine wakes a passive garbage collector when its mutator starts waiting, allowing collection to progress when shared GC helpers are occupied elsewhere. A native regression checks the late-wait transition, completion before helper release, and survival of rooted objects.

Budgeted workers use young-generation collections and bound post-full-collection growth independently of machine-wide RAM. Full collections still verify heap-limit exhaustion. Idle collection requires the matching immediate GC timer wakeup in [Bun #129](https://github.com/openclaw/bun/pull/129); include that companion when consuming this engine.

The previously released worker termination and allocator fixes remain included. The engine delivers pending worker heap-limit termination promptly after GC. It invalidates optimized code at the mutator's collection epilogue so existing JavaScript safe points deliver the pending trap without repeated full collections. Full-GC managed live accounting, heap budgets and ArrayBuffer exclusions are unchanged. Native regressions cover termination after one over-cap full collection and near-limit survival; Bun qualification retains the worker OOM event contract and external-buffer controls.

Expand All @@ -21,9 +31,9 @@ Other previously released engine changes remain included:
- Synchronize the accounting-related parallel-helper assertion and visited-memory counters.
- Preserve syntax-selected stack positions for calls, constructors, property reads and async continuations, including live/captured stacks and cache replay; thanks @robobun for the upstream source-position work.

Qualification includes all ten artifact builds, Linux JSC module/promise/namespace/Segmenter and allocation-sampling regressions, the paired Bun selection, a build of the exact prepared upstream-synced Bun runtime with its required namespace API adapter and candidate manifest with startup and unchanged upstream memory-release tests, and a separate build with feature adapters for the complete fork selection and patch regressions. Syntax-selected stack positions are checked across execution tiers, live/captured stacks, and cache replay. Other targets have build/provenance proof; native runtime qualification additionally covers macOS and Linux ARM64 assembler/JSC regressions, and Windows ARM64 JSC startup, DFG JIT, FFI and five ArrayBuffer accounting modes. Bun consumer qualification is separate.
Qualification includes all ten artifact builds, Linux JSC module/promise/namespace/Segmenter and allocation-sampling regressions, the paired Bun selection, a build of the exact prepared upstream-synced Bun runtime with its required namespace API adapter and candidate manifest with startup and unchanged upstream memory-release tests, and a separate build with feature adapters for the complete fork selection and patch regressions. Syntax-selected stack positions are checked across execution tiers, live/captured stacks, and cache replay. Separate native Linux ARM64 checks cover assembler and JSC regressions. Native Windows ARM64 qualification covers JSC startup, DFG JIT, FFI and five ArrayBuffer accounting modes. macOS and the remaining targets have compilation and provenance proof for this batch. Bun consumer qualification is separate.

The new engine requires Bun's updated mimalloc idle hook and matching embedding adapters. A manifest-only update of the original sync tree does not compile: its old namespace marker access must be replaced by the namespace adapter (Bun #106), paired atomically with this engine. Consumers must rebuild with the manifest's exact headers and libraries; an older executable is not interchangeable.
The existing embedding requirements remain: Bun's mimalloc idle hook and matching adapters. A manifest-only update of the original sync tree does not compile: its old namespace marker access must be replaced by the namespace adapter (Bun #106), paired atomically with this engine. Consumers must rebuild with the manifest's exact headers and libraries; an older executable is not interchangeable.

Source and licenses: LICENSE-SOURCES.txt. Checksums: SHA256SUMS and manifest.json. Build and qualification evidence: provenance.tar.gz.

Expand Down
11 changes: 6 additions & 5 deletions OPENCLAW.md
Original file line number Diff line number Diff line change
Expand Up @@ -101,11 +101,7 @@ Keep every prior release. Revert the Bun manifest and WebKit source pin together
then rebuild Bun against that matched engine. Never replace a published asset or
use an old Bun executable with headers/libraries from another engine ABI.

## Unreleased

- Initialize new VM entry scratch buffers and alignment padding before entering JavaScript or native callees, preventing stale stack values from retaining otherwise unreachable objects during collection.
- Store deferred microtask entry scopes as two initialized pointers, avoiding stale optional-flag padding that can conservatively retain lexical environments and cancellation reasons.
- Verify dead-realm cleanup with the collected-realm fixture from openclaw/bun#151, adapted from oven-sh/bun#44544; thanks @robobun. Retain the qualified Linux Bun executables and hashes for three days, including failed qualification runs.
## VM entry storage

The paired qualifier keeps its frozen Bun source and applies the test-only fix
from `4c8accdd045b84c942fe447348a31a7cba04cde4` to both arms. The feature-sync
Expand Down Expand Up @@ -174,6 +170,11 @@ baseline. Engine and Bun headers and libraries must be rebuilt together.

## Unreleased

## Stack retention and Linux suspension (2026-10-09)

- Initialize new VM entry scratch buffers and alignment padding before entering JavaScript or native callees, preventing stale stack values from retaining otherwise unreachable objects during collection.
- Store deferred microtask entry scopes as two initialized pointers, avoiding stale optional-flag padding that can conservatively retain lexical environments and cancellation reasons. Adapts the whole-word-state remedy in oven-sh/WebKit#694; thanks @robobun.
- Verify dead-realm cleanup with the collected-realm fixture from openclaw/bun#151, adapted from oven-sh/bun#44544; thanks @robobun. Retain the qualified Linux Bun executables and hashes for three days, including failed qualification runs.
- Retry asynchronous VM trap delivery after a foreign-stack suspension refusal without holding the process-wide suspension lock, allowing other VMs to collect while native calls await them. Blocking GC suspension and Mach suspension retain their existing contracts.

## Passive collector progress and worker cadence (2026-10-07)
Expand Down